UK financial sector rehearses global cloud disruption with 38 institutions

The Bank of England expects firms to act on lessons from SIMEX26, which brought major banks and market infrastructure operators together. Detailed results have not been published.

The Bank of England building in London.
File photograph of the Bank of England building in London, taken in July 2022. acediscovery (resized and converted to WebP). CC BY 4.0.
LinkedInPostEmail
Save for later

The Bank of England announced on 9 October that 38 major banks and market infrastructure operators had completed a UK financial-sector exercise on 8 October 2026 simulating a global disruption to cloud services. The rehearsal tested the sector’s coordinated crisis response, and the Bank now expects firms to act on its lessons to strengthen their ability to maintain critical services.

Known as SIMEX26, the biennial exercise was organised through the Cross-Market Operational Resilience Group, or CMORG. The Bank described the participants as the largest and most systemically important banks and market infrastructure operators; the total of 38 covers both groups.

How SIMEX26 rehearsed a cloud disruption

CMORG is chaired by the Bank and UK Finance, with participation from HM Treasury, the Financial Conduct Authority and the wider financial sector. London Stock Exchange Group hosted the exercise, which was opened by Economic Secretary to the Treasury Lucy Rigby.

Firms worked alongside financial authorities on the global cloud-disruption scenario. The exercise also included a live meeting of the Bank-chaired Cross Market Business Continuity Group, which provides strategic direction for the sector’s collective response to systemic incidents.

CMORG oversees the Sector Response Framework, a mechanism for coordinating the financial sector’s response to systemic incidents, which is exercised through SIMEX. The Bank said the scenario was developed with industry experts and was not based on specific threat information.

In its announcement, the Bank said it expected firms to take action based on the exercise to strengthen their resilience and ability to respond to severe operational and cyber scenarios.

Katharine Braddick, the Bank’s deputy governor of prudential regulation and chief executive of the Prudential Regulation Authority, described the collaboration as reflecting firms’ commitment to maintaining critical services during disruption. She said: “That preparedness is essential to safeguarding financial stability.”

UK Finance chief executive David Postings assessed the exercise as an opportunity to strengthen the sector’s response. He said: “SIMEX 2026 enabled us to collectively strengthen preparedness and ensure the sector is better equipped to respond to significant disruptive events while continuing to deliver essential services to customers.”

Why shared cloud dependencies matter

The risks behind the scenario have been examined beyond the UK. In a report released on 8 February 2023, the U.S. Treasury said cloud services could improve financial institutions’ security and resilience, while creating operational challenges that could detract from those benefits.

Treasury warned that concentration among a small number of cloud providers could expose numerous financial clients to the same incident. It identified significant gaps in the data needed to assess sector-wide effects, alongside practical obstacles to moving operations to another provider.

Its report also recorded community banks’ concerns about receiving insufficient information on incidents affecting their systems, and shortages of cloud expertise and supporting tools. Further public-private tabletop exercises were among its proposed responses. These were findings about the US financial sector in 2023, rather than assessments of SIMEX26 participants.

The Treasury report drew on regulators, industry stakeholders, trade associations and think tanks. It imposed no requirements and did not endorse or discourage the use of any particular provider or cloud service.

The Financial Stability Board’s December 2023 toolkit separately warned that expanding third-party relationships could create financial-stability risks if poorly managed. Its flexible, risk-based tools cover identifying critical services, managing supplier relationships, supervising firms’ controls and monitoring systemic dependencies. The toolkit complements existing standards and does not evaluate SIMEX26.

What the Bank has disclosed about results

Earlier SIMEX exercises in 2022 and 2024 considered cyber-attacks against a major bank and disruption to critical infrastructure outside finance. The Bank’s announcement does not specify which of those scenarios belonged to which year.

For SIMEX26, the Bank has provided no participant-by-participant results, recovery-time measurements or detailed deficiencies. It has not identified all 38 participants or any cloud providers involved. The published account therefore offers no independent measurement of how firms would withstand a real global cloud disruption.

The next step outlined by the Bank is action by participating firms. Its announcement sets no specific remediation deadlines and gives no timetable for publishing a public lessons report, leaving the precise changes arising from the rehearsal undisclosed.

Sources and context

AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.

About NewsJaws Desk

AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.